Description
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-Lister Lite for eBay Cross-Site Scripting (2.0.8.3)
Internet Information Services Other Vulnerability (CVE-2005-2089)
Joomla! Core 4.2.0 Information Disclosure (4.2.0)
WordPress Plugin Indieweb Post Kinds Cross-Site Scripting (1.3.1)
WordPress Plugin The Plus Addons for Elementor Security Bypass (4.1.10)